{"resultsPerPage":1,"startIndex":0,"totalResults":1,"format":"NVD_CVE","version":"2.0","timestamp":"2026-08-01T11:56:19.200","vulnerabilities":[{"cve":{"id":"CVE-2024-29974","sourceIdentifier":"security@zyxel.com.tw","published":"2024-06-04T02:15:48.517","lastModified":"2026-06-17T07:23:28.407","vulnStatus":"Analyzed","cveTags":[{"sourceIdentifier":"security@zyxel.com.tw","tags":["unsupported-when-assigned"]}],"descriptions":[{"lang":"en","value":"** UNSUPPORTED WHEN ASSIGNED **\nThe remote code execution vulnerability in the CGI program “file_upload-cgi” in Zyxel NAS326 firmware versions before V5.21(AAZF.17)C0 and NAS542 firmware versions before V5.21(ABAG.14)C0 could allow an unauthenticated attacker to execute arbitrary code by uploading a crafted configuration file to a vulnerable device."},{"lang":"es","value":"** NO SOPORTADO CUANDO SE ASIGNÓ ** La vulnerabilidad de ejecución remota de código en el programa CGI “file_upload-cgi” en las versiones de firmware Zyxel NAS326 anteriores a V5.21(AAZF.17)C0 y versiones de firmware NAS542 anteriores a V5.21(ABAG.14)C0 podría permitir que un atacante no autenticado ejecute código arbitrario cargando un archivo de configuración manipulado en un dispositivo vulnerable."}],"affected":[{"source":"security@zyxel.com.tw","affectedData":[{"vendor":"Zyxel","product":"NAS326 firmware","defaultStatus":"unaffected","versions":[{"version":"< V5.21(AAZF.17)C0","status":"affected"}]},{"vendor":"Zyxel","product":"NAS542 firmware","defaultStatus":"unaffected","versions":[{"version":"< V5.21(ABAG.14)C0","status":"affected"}]}]},{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","affectedData":[{"vendor":"zyxel","product":"nas326_firmware","defaultStatus":"unknown","cpes":["cpe:2.3:o:zyxel:nas326_firmware:-:*:*:*:*:*:*:*"],"versions":[{"version":"0","lessThan":"v5.21\\(aazf.17\\)co","versionType":"custom","status":"affected"}]},{"vendor":"zyxel","product":"nas542_firmware","defaultStatus":"unknown","cpes":["cpe:2.3:o:zyxel:nas542_firmware:-:*:*:*:*:*:*:*"],"versions":[{"version":"0","lessThan":"5.21\\(abag.14\\)co","versionType":"custom","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"security@zyxel.com.tw","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","baseScore":9.8,"baseSeverity":"CRITICAL","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH"},"exploitabilityScore":3.9,"impactScore":5.9}],"ssvcV203":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","ssvcData":{"timestamp":"2024-06-04T15:08:52.235583Z","id":"CVE-2024-29974","options":[{"exploitation":"none"},{"automatable":"yes"},{"technicalImpact":"total"}],"role":"CISA Coordinator","version":"2.0.3"}}]},"weaknesses":[{"source":"security@zyxel.com.tw","type":"Secondary","description":[{"lang":"en","value":"CWE-434"}]}],"configurations":[{"operator":"AND","nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:o:zyxel:nas326_firmware:*:*:*:*:*:*:*:*","versionEndExcluding":"5.21\\(aazf.17\\)c0","matchCriteriaId":"DF437A28-8199-4AB6-9F07-F061994C0D9C"}]},{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":false,"criteria":"cpe:2.3:h:zyxel:nas326:-:*:*:*:*:*:*:*","matchCriteriaId":"E0A01B19-4A91-4FBC-8447-2E854346DAC5"}]}]},{"operator":"AND","nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:o:zyxel:nas542_firmware:*:*:*:*:*:*:*:*","versionEndExcluding":"5.21\\(abag.14\\)c0","matchCriteriaId":"718ACAC1-C0E1-45DF-A23E-7A7F9CCF1373"}]},{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":false,"criteria":"cpe:2.3:h:zyxel:nas542:-:*:*:*:*:*:*:*","matchCriteriaId":"31C4DD0F-28D0-4BF7-897B-5EEC32AA7277"}]}]}],"references":[{"url":"https://outpost24.com/blog/zyxel-nas-critical-vulnerabilities/","source":"security@zyxel.com.tw","tags":["Exploit","Third Party Advisory"]},{"url":"https://www.zyxel.com/global/en/support/security-advisories/zyxel-security-advisory-for-multiple-vulnerabilities-in-nas-products-06-04-2024","source":"security@zyxel.com.tw","tags":["Vendor Advisory"]},{"url":"https://outpost24.com/blog/zyxel-nas-critical-vulnerabilities/","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Exploit","Third Party Advisory"]},{"url":"https://www.zyxel.com/global/en/support/security-advisories/zyxel-security-advisory-for-multiple-vulnerabilities-in-nas-products-06-04-2024","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Vendor Advisory"]}]}}]}